Device & Update
Management
Professional Update Management for IoT Device Fleets—From OTA Campaigns to Auditable Fleet Operations
Are you looking for a solution to centrally manage software and security updates across thousands of devices –—including wave deployment, rollback, and audit-ready documentation? Or is your fleet growing, and can you no longer scale onboarding, operations, and compliance manually? Device & Update Management addresses both of these challenges.
Update Management is the core component—supplemented by Device Management, Remote Access, alerting, and compliance—all in an integrated solution—tailored to your device landscape and integration requirements, available as a complete solution or for integration into existing systems.
You can centrally manage software and security updates and roll them out in a controlled manner across target groups and waves—using an SSO-enabled web interface, rule-based rollout control, and comprehensive audit trails. The solution can be operated in the cloud, on-premises, or in a hybrid environment—tailored to your IT/OT landscape and compliance requirements.
The implementation of the Update Manager has significantly improved our ability to distribute updates efficiently and securely. Thanks to this solution, we can keep all our networked systems up to date globally. This enhances the user experience and security, and improves our product’s performance thanks to new features in the rolled-out software. – Luca Lutsch, Product Owner at ZEISS Microscopy
As the fleet grows, manual processes don't scale with it
Connected device fleets are growing faster than the ability to operate them manually.
Many manufacturers and operators are familiar with this situation:
- Device status, software versions, and malfunctions are not visible centrally –, making it impossible to get a reliable overview of the fleet.
- Heterogeneous device types, protocols, and platforms lead to siloed solutions and high integration costs.
- Provisioning and onboarding are inconsistent—devices are not put into service in a consistent, secure, and scalable manner.
- Updates cannot be rolled out in a targeted, phased manner with rollback capabilities; dependencies and rollout windows increase the risk of downtime.
- Remote maintenance is unreliable or not logged—On-site visits remain expensive.
- Thresholds, outages, and security incidents are detected too late; rule-based escalations are lacking.
- No comprehensive overview of software in the field—Vulnerability management and CRA-compliant documentation are virtually impossible.
- Evidence for CRA and NIS2—Patches, accesses, and software versions—are incomplete or cannot be audited.
The result: rising operating costs, growing compliance gaps, increased cyber risks in the field, and a reactive approach instead of predictable fleet operations.
An Integrated Solution –
Focus on Update Management
The focus is on update management: OTA campaigns with a phased rollout strategy, target group control, rollback, and auditable history. Around this core, Device & Update Management brings together everything needed for secure fleet operations—inventory and onboarding, remote access, alerting, and compliance throughout the device lifecycle.
Instead of building custom solutions from scratch, doubleSlash and you rely on proven solution components and reference architectures from industry projects –—tailored to your device landscape and integrable with ThingWorx, Azure, AWS, mender.io, Eclipse hawkBit, and other systems. doubleSlash orchestrates and manages updates via a central interface and integrates/bundles existing systems rather than replacing them.
Typical Process in Practice:
- Securely onboard devices and manage them in the inventory.
- Roll out software and security updates via OTA—in waves, with rollback capabilities and a documented history.
- Monitor the fleet, detect issues early, and provide controlled remote support as needed.
- Ensure that operations and changes are traceable for audits and compliance.
No devices connected yet? Device Connectivity is the first step.
What You Can Win
Shorter time-to-patch:
OTA campaigns with phased rollouts and target group control replace manual, individual maintenance. A controlled rollout typically takes days to a few weeks, whereas on-site maintenance often takes weeks. At ZEISS Microscopy, more than 5,000 microscopes worldwide are maintained centrally in this way.
Speed:
Proven solution components and reference architectures speed up the path to productivity. A focused pilot typically goes live in 4 to 6 weeks; with a lean scope, it often goes live in about 4 weeks.
Choose Your Deployment Model Flexibly:
Cloud, on-premises, or hybrid—the choice depends on your requirements regarding data sovereignty, latency, and compliance. We’ll determine which model is right for you during a needs assessment.
Security by Design:
Logging, roles and permissions, encryption, signature verification, and patch management are built into the solution from the start, ensuring that every remote session and every update step remains traceable.
Fewer On-Site Visits:
Remote support and targeted alerts reduce the mean time to repair. In established setups, software, update, and configuration issues typically account for about 50 to 70% of on-site visits. Hardware and mandatory service calls remain necessary.
Compliance:
Coordinated updates and documented evidence for CRA and NIS2 provide audit trails and patch reports that can be used to prepare for audits.
Transparency:
A centralized view of device and software versions, campaign status, and risks across locations and device types. In reference projects, the scope of management ranges from hundreds to several thousand devices.
Note on the figures:
These are approximate values based on projects and case studies; the actual effect depends on your specific situation.
What Device & Update Management Does
Update management is at the core—the other areas are what make secure, scalable fleet operations feasible in the first place. Depending on the initial situation and requirements, we combine the relevant components—not every project needs all the features right from the start.
Device Management
Update Management
Remote Access
Notifications and Alerts
Compliance and Monitoring
Our Technological Expertise
Two Approaches to Implementation
Same Objective, Different Levels of Integration
Both approaches serve as entry points for a shared, customized implementation of—not fixed product packages.
The specific features (Update Management, Device Management, Remote Access, Alerting, Compliance) to be implemented are determined during the needs assessment.
Instead of developing everything from scratch, we provide proven solution components and tested reference architectures from industry projects featuring—for OTA campaigns, fleet operations, remote access, and compliance.
What works is adopted. What doesn’t work is adapted.
CRA and NIS2:
Ensuring Updates Are Traceable
The Cyber Resilience Act requires manufacturers of connected products to provide regular security updates and document them. NIS2 adds requirements regarding security processes and evidence management. Without a centralized inventory, controllable OTA processes, and logged remote access, these requirements cannot be met in a practical manner in the field.
Device & Update Management addresses this through coordinated update rollouts, comprehensive documentation, transparency regarding software versions, and reporting artifacts for audits. doubleSlash provides technical and organizational implementation support—not legal advice on a case-by-case basis.
For machinery and plant manufacturers with brownfield fleets, we recommend starting with the Readiness Check, then moving on to the brownfield retrofit and finally to the fleet roll-out: Retrofit to CRA Readiness, continue operating existing machinery
Post-Market Surveillance
Classify incidents in the field and resolve them in a verifiable manner
Post-market surveillance requires reliable device data—and the ability to quickly identify affected devices, software versions, and corrective actions. This is particularly relevant in medical technology (MDR) and in mechanical and plant engineering (ISO-based quality and risk management systems).
Manufacturers of connected products must systematically monitor devices after they enter the market: collect reports and signals from the field, classify incidents, determine the causes, and implement corrective actions in a transparent manner.
Device & Update Management provides the technical foundation for this process:
- Field Observation
Centrally manage inventory, status, and software versions—which devices and versions are on the market. - Incident Logging and Alerts
Detect malfunctions, threshold violations, and notifications early through monitoring and alerting. - Technical and Regulatory Classification
Investigate and classify incidents using device history, configuration, and remote access –—the basis for determining criticality and next steps.
- Traceability and Correction
Identify affected devices and versions; roll out security and functional updates as a controlled OTA campaign—including campaigns, rollbacks, and documented history. - Verification and Improvement
Audit trails and reporting for CAPA, audits, and continuous improvement—compatible with existing QMS and compliance processes.
In this way, post-market surveillance does not become merely a matter of retrospective documentation, but rather an end-to-end operational process –—from field monitoring to verifiable corrective action.
Questions & Answers
Fundamentals and Classification
What is IoT device management, and why do I need it?
What is Device & Update Management?
Which IoT management solution is right for my fleet?
Problem, Benefits, and Relevance
What challenges arise when scaling an IoT device fleet?
Benefits of Centralized IoT Device Management
Features, Technology, and Operation
How can IoT devices be updated securely?
How does remote access work securely?
Which IoT platforms are supported?
Where is my data stored—in the cloud, on-premises, or in a hybrid environment?
Implementation and Collaboration
How do we get started?
How soon will the first results be visible?
What will I receive after the implementation?
What is the pricing logic?
Compliance and Regulation
How does the solution support CRA and NIS2?
Request a Demo and Consultation
